CVE-2007-3006
Acoustica MP3 CD Burner 4.32 - Buffer Overflow via ASX Playlist REF HREF Attribute
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-3006. PoCs published by Koshi, n00b.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Acoustica MP3 CD Burner via a malformed ASX file. It uses a SEH-based exploit technique with a calc.exe payload encoded in Alpha2.
Description
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF element containing a long string in the HREF attribute. NOTE: it was later claimed that 4.51 Build 147 is also affected.
Exploits (2)
This exploit targets a buffer overflow vulnerability in Acoustica MP3 CD Burner via a malformed ASX file. It uses a SEH-based exploit technique with a calc.exe payload encoded in Alpha2.
This is a proof-of-concept exploit for CVE-2007-3006, demonstrating a local buffer overflow in Acoustica MP3 CD Burner 4.32 via a crafted .asx playlist file. The PoC overwrites EIP with 'A's (0x41) to trigger an access violation, proving control over execution flow.